Skip to content
AscendCore

Security & Compliance

Six controls a CISO signs off on. Before pilot.

AscendCore was architected for CISOs and CIOs, not just help-desk managers. Every action is gated by a named-admin approval, every credential lives in its own logical vault, and every execution appends to a SHA-256 audit chain.

Read the security overview

100%

Actions require a named-admin approval. No exceptions, no autopilot mode.

Architecture ledger

06 controls

01

Logical vault, per org

Per-Organization Isolation

02

Named-admin gate · 100% HITL

Approval-First Execution

03

SHA-256 hash chain · Postgres

Tamper-Evident Audit Chain

04

HMAC-SHA256 · JWT

Verified Webhook Integrity

05

Server-enforced · OIDC SSO

RBAC + SSO

06

TLS 1.3 · AES-256

Encryption In Transit & At Rest

The proof

One chain. Every decision. Provable.

Every approve, deny, and execution appends to a tamper-evident SHA-256 chain backed by Postgres. Each record's hash includes the prior record's hash. Export it as CSV, re-hash it from genesis, and check it offline. The proof is the customer's, not ours.

SOC 2 Type I is planned. This export is evidence you can hand an auditor, not a compliance certification.

Verify it live Not verified by us. Verifiable by you.

GOVERNANCE · AUDIT CHAIN

seqactionactorthis_hash
0003mfa_reset.approveda.morgan9f4d2a8c…1b3d
0004account_unlock.approveda.morgan7c3a1f9d…d1f3
0005offboard.approveda.morgana3f5b9c1…d8e0
0006role_change.executedsystemb1c7e4f2…3a9d
0007license_assign.approveds.chene8d21c47…6b2f

✓ chain re-computed from genesis. every value matched.

simulated preview, real grammar · the live chain is verifiable in the demo

Security posture · Verifiable

Verifiable today. Roadmap disclosed.

The controls a CISO will ask about, split honestly: what's enforced in production right now, and what's on the audit calendar.

Live in production today

Enforced

Logical vault, per org

Per-Organization Isolation

Each org's integration secrets (Okta, Entra, M365, Slack) are scoped to that org and managed in Doppler. Credentials resolve only for that org's traffic, namespaced across the audit chain and operational store.

Enforced

Named-admin gate · 100% HITL

Approval-First Execution

Every runbook stops at an explicit human sign-off before it touches production. No autonomous actions. Idempotent retries prevent double-execution under network failure or a double-tap.

Enforced

SHA-256 hash chain · Postgres

Tamper-Evident Audit Chain

Every approve, deny, and execution appends to a Postgres-backed SHA-256 hash chain. Each row links to the prior row's hash, so a single altered row breaks verification. Customer-exportable for independent proof.

Export the audit chain
Enforced

HMAC-SHA256 · JWT

Verified Webhook Integrity

Inbound Slack requests are verified via HMAC-SHA256 with timing-safe comparison; inbound Teams activities via JWT against Microsoft's public JWKS. Spoofed requests are rejected at the edge.

Enforced

Server-enforced · OIDC SSO

RBAC + SSO

Owner / Demo / Guest roles enforced server-side on every mutation. OIDC SSO for admin login (Microsoft Entra + Okta), with optional mandatory-SSO so your IdP brokers MFA and conditional access.

Enforced

TLS 1.3 · AES-256

Encryption In Transit & At Rest

TLS 1.3 in transit at the Netlify edge; AES-256 at rest for all stored data (Cloudflare R2, Netlify Blobs, Neon). No plaintext secrets on disk or in logs.

31 production runbooksGDPR-aware DPAEncrypted secret vaults (Doppler)US data residency (US East 2)Per-IP + per-key rate limitingIdempotent execution99.5% SLA commitment1,300+ automated tests

On the roadmap

SOC-2 Type I

~90-day window

Vanta enrollment planned (begins once budgeted); a ~90-day audit window then certification. The underlying controls, data-retention, and incident-response policies are already live and enforced today.

Independent penetration test

Q3 2026

Third-party assessment ahead of first enterprise deployments. Reports available under NDA for active procurement.

SOC-2 Type II

H2 2027

Follows Type I plus an observation period.

ISO 27001

2027

Post-SOC-2 alignment for international procurement. Not yet mapped or certified.

Customer-managed keys (BYOK)

H1 2027

Bring-your-own-KMS for application-level data encryption.

Security cleared? See what a pilot looks like.

Items move from roadmap to live via dated commits and changelog entries. For status against a specific control, email security@ascendcore.ai.

Sub-processors

The third-party services that may process customer data while delivering AscendCore. Updated whenever we add or remove a vendor; see the timestamp at the top of this page.

VendorPurposeRegionTerms
AnthropicLLM inference (intent classification)USNo training on API data per Anthropic terms
Slack TechnologiesBot framework + slash commandsUSStandard Slack DPA
Microsoft (Bot FW, Graph, Entra)Teams bot, Microsoft 365 / Entra automationsUS/EUMicrosoft DPA + EU SCCs
Cloudflare R2Object storage at rest (AES-256)USCloudflare DPA
NetlifyApplication hosting + edge functions + BlobsUSNetlify DPA
NeonPostgres database for tamper-evident audit chainUSNeon DPA · US East 2 region
DopplerSecret management with auditable secret accessUSDoppler DPA
ResendTransactional email (notifications)USResend DPA
PostHogProduct analytics (anonymized after consent)US/EUPostHog DPA · cookie-consent gated
VantaCompliance automation (after enrollment)USVanta DPA · enrollment planned (begins once budgeted)
CISO FAQ

Questions we get from security teams.

Honest answers, including for the things we're still building.

Want to verify any specific control?

We'll do a technical review call, walk through architecture in detail, share our internal audit findings under NDA, or answer specific items on your enterprise security questionnaire.

Ready to take L1 off your queue?

AscendCore is onboarding private-beta pilots now. Onboarding takes days, not months, with human-in-the-loop approval on every action.

No credit card required. 30-day pilot. Cancel anytime.